Head to head · Agent multi agent · October 2026 research run

Kilo Code CLI vs Paperclip

Kilo Code CLI scores 75.4 (BB) on agent readiness against Paperclip's 59 (C), and leads in 6 of 7 scored categories. Paperclip leads on payments & pricing. Both do agent multi agent.

Which one, for what

Kilo Code CLI BB

Good for Developers who want an open-source terminal agent with per-tool permission rules, an optional sandbox and a choice of provider, and the same engine in VS Code and JetBrains.

Ahead on

  • Reliability, 85 against 66
  • Schema & documentation, 90 against 81
  • Maintenance & community, 87 against 78
  • Transparency & trust, 76 against 65

Also in its favour

  • Agent-ready, a grade of BB or better
  • No incidents deducted, where Paperclip loses 10 points for them

Watch for

Telemetry to PostHog is on by default, and the privacy policy and PRIVACY.md don't mention it

Paperclip C

Good for Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.

Ahead on

  • Payments & pricing, 60 against 50

Watch for

claude_local defaults dangerouslySkipPermissions to true and codex_local defaults to bypassing approvals and the sandbox, with agents running on the host

Score by category

CategoryWeight this runKilo Code CLIPaperclipEdge
Reliability16%208566Kilo Code CLI +19
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29081Kilo Code CLI +9
Agent ergonomics13%16.27270Kilo Code CLI +2
Security & auth14%17.56664Kilo Code CLI +2
Payments & pricing10%12.55060Paperclip +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88778Kilo Code CLI +9
Transparency & trust7%8.87665Kilo Code CLI +11
Negative events≤150-10
Total75.4 · BB59 · C

Facts side by side

FactKilo Code CLIPaperclip
KindAgent harnessAgent harness
VendorKilo Code Inc.Paperclip Labs, Inc.
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyOAuth or key
PricingFreemiumFree
x402nono
LicenceMITMIT
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-072026-10-05
Terms last updated2026-09-302026-07-23
Privacy policy last updated2026-05-292026-07-23
Customer content may train modelsnot found in the textyes, with an opt-out
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waiveryesyes
Popularity28k stars, 33k npm/wk99k stars, 60k npm/wk

Verdicts

Kilo Code CLI

Shell commands ask before running by default, and an optional operating-system sandbox blocks writes outside the workspace and outbound network. Telemetry to PostHog is on by default and the sandbox is off, so an unattended kilo run --auto approves everything not denied unless both are configured first.

Paperclip

Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026.

Before you call either

Kilo Code CLI

  1. Set sandbox.enabled to true in the global kilo.jsonc before kilo run --auto. --auto approves every permission request not explicitly denied
  2. Set experimental.openTelemetry to false, or KILO_TELEMETRY_LEVEL to a value other than all, to stop telemetry
  3. Add needed hosts to sandbox.allowed_hosts in global config. MCP tool calls are unavailable while network restriction is on
  4. Without --auto a non-interactive run rejects every permission prompt and exits 1
  5. Put provider keys in global config or the environment. {env:VAR} in a project kilo.json is ignored

Paperclip

  1. Set PAPERCLIP_TELEMETRY_DISABLED=1 or DO_NOT_TRACK=1 before the first start. Telemetry is on by default
  2. Set dangerouslySkipPermissions and dangerouslyBypassApprovalsAndSandbox to false on agents that read untrusted input, or run them in a sandbox provider
  3. Install with Node.js 24.11 or newer, and install and sign in to each harness CLI on the host first. Paperclip assumes they are there
  4. Use --bind lan or --bind tailnet at onboarding for anything beyond one machine. The default local_trusted mode treats every request as the board admin
  5. Treat 409 on task checkout as owned by another agent and pick different work. The API docs say not to retry

Questions

Which is better for AI agents, Kilo Code CLI or Paperclip?

Kilo Code CLI scores 75.4 (BB) on agent readiness against Paperclip's 59 (C), and leads in 6 of 7 scored categories. Paperclip leads on payments & pricing.

Are Kilo Code CLI and Paperclip open source?

Yes. Kilo Code CLI is open source (MIT). Paperclip is open source (MIT).

Other comparisons with Kilo Code CLI or Paperclip

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.